Revert OL modifications

This commit is contained in:
AlmaLinux RelEng Bot 2026-07-21 09:49:39 -04:00
parent 2a2b4d0d64
commit babe43de03
2 changed files with 1 additions and 31 deletions

View File

@ -1,26 +0,0 @@
From: Alex Burmashev <alexander.burmashev@oracle.com>
Date: Tue, 04 May 2021 13:31:41 +0100
Subject: [PATCH] restore default debug level for sss_cache
We want only fatal failures to be logged, otherwise in some conditions log is.
flooded with unneeded "errors"
Resolves: https://github.com/SSSD/sssd/issues/5488
Orabug: 32810448
Signed-off-by: Alex Burmashev <alexander.burmashev@oracle.com>
Patch migrated from ol8 to ol9 without any modification
Signed-off-by: Darren Archibald <darren.archibald@oracle.com>
diff -uNr a/src/tools/sss_cache.c b/src/tools/sss_cache.c
--- a/src/tools/sss_cache.c 2024-06-26 02:11:39.000000000 -0700
+++ b/src/tools/sss_cache.c 2024-09-05 16:17:12.686336046 -0700
@@ -722,7 +722,7 @@
struct cache_tool_ctx *ctx = NULL;
int idb = INVALIDATE_NONE;
struct input_values values = { 0 };
- int debug = SSSDBG_TOOLS_DEFAULT;
+ int debug = SSSDBG_FATAL_FAILURE;
errno_t ret = EOK;
poptContext pc = NULL;

View File

@ -21,13 +21,12 @@
Name: sssd
Version: 2.12.0
Release: 3.0.1%{?dist}.1
Release: 3%{?dist}.1
Summary: System Security Services Daemon
License: GPL-3.0-or-later
URL: https://github.com/SSSD/sssd/
Source0: https://github.com/SSSD/sssd/releases/download/2.12.0/sssd-2.12.0.tar.gz
Source1: sssd.sysusers
Patch2002: 2002-orabug32810448-restore-default-debug-sss_cache.patch
### Patches ###
Patch1: 0001-do-not-require-GID-for-non-POSIX-group.patch
@ -1093,9 +1092,6 @@ fi
%systemd_postun_with_restart sssd.service
%changelog
* Mon Jul 20 2026 EL Errata <el-errata_ww@oracle.com> - 2.12.0-3.0.1.el10_2.1
- Restore default debug level for sss_cache [Orabug: 32810448]
* Wed Jul 8 2026 - Tomas Halman <thalman@redhat.com> - 2.12.0-3.1
- Resolves: RHEL-192056 - CVE-2026-14474 sssd: sssd: sudo LDAP provider searches entire directory tree for sudoRole
- Resolves: RHEL-192064 - CVE-2026-14476 sssd: sssd: GPO cache path traversal via unsanitized gPCFileSysPath allows Kerberos authentication bypass